Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,551
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,201 - 2,220 of 28,420 CVEs
CVE-2020-37238 MEDIUM - 6.4

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other a...

Vendor: Cmsmadesimple
Product: CMS Made Simple
Published: May 16, 2026
Source: NVD
CVE-2020-37237 MEDIUM - 6.4

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality...

Vendor: Compo
Product: Composr CMS
Published: May 16, 2026
Source: NVD
CVE-2020-37236 MEDIUM - 6.4

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the admin panel that exe...

Vendor: Netartmedia
Product: NewsLister
Published: May 16, 2026
Source: NVD
CVE-2020-37235 MEDIUM - 6.4

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encode...

Vendor: themeftc
Product: Theme Wibar
Published: May 16, 2026
Source: NVD
CVE-2020-37234 MEDIUM - 6.2

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' fiel...

Vendor: Internetdownloadmanager
Product: Internet Download Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37233 MEDIUM - 6.4

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onloa...

Vendor: Wordpress
Product: Buddypress
Published: May 16, 2026
Source: NVD
CVE-2020-37232 HIGH - 7.8

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be executed with LocalSystem ...

Vendor: Iobit
Product: Advanced System Care Service
Published: May 16, 2026
Source: NVD
CVE-2020-37231 HIGH - 7.8

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with...

Vendor: Cybertronsoft
Product: Privacy Drive
Published: May 16, 2026
Source: NVD
CVE-2020-37230 HIGH - 7.8

Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path. Attackers can insert a malicious executable into the service path and execute it with LocalSystem p...

Vendor: Syncplify
Product: Syncplify.me Server!
Published: May 16, 2026
Source: NVD
CVE-2020-37229 HIGH - 7.8

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unquoted path. Attackers can place a malicious executable in a directory within the service path that wil...

Vendor: Oki
Product: OKI sPSV Port Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37228 CRITICAL - 9.8

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against u...

Vendor: Yerootech
Product: iDS6 DSSPro Digital Signage System
Published: May 16, 2026
Source: NVD
CVE-2020-37227 HIGH - 8.8

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to exe...

Vendor: Heliossolutions
Product: HS Brand Logo Slider
Published: May 16, 2026
Source: NVD
CVE-2026-46719 MEDIUM - 6.5

Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Vendor: RRWO
Product: Net::Statsd::Lite
Published: May 16, 2026
Source: NVD
CVE-2025-4202 MEDIUM - 4.3

The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf_add_comment' function in all versions up to, and including, 5.2. This makes it possible for authenticated ...

Published: May 16, 2026
Source: NVD
CVE-2026-8657 HIGH - 8.2

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property ...

Published: May 16, 2026
Source: NVD
CVE-2026-8656 MEDIUM - 6.1

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacke...

Published: May 16, 2026
Source: NVD
CVE-2026-8681 MEDIUM - 5.3

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin...

Published: May 16, 2026
Source: NVD
CVE-2026-8704 MEDIUM - 6.5

Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.

Published: May 15, 2026
Source: NVD
CVE-2026-8700 HIGH - 7.3

Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Published: May 15, 2026
Source: NVD
CVE-2026-8696 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD